Software Secure Workload
Activity Configure

Limits Related to Policies

Feature

Metric

Limit

Automatic policy discovery (formerly ADM)

Maximum number of member workloads (endpoints) allowed for automatic policy discovery run on a single scope.

10,000

Maximum number of conversations allowed for automatic policy discovery run on a single scope.

10,000,000

Maximum number of member workloads (endpoints) allowed for automatic policy discovery on a branch of the scope tree.

37,500

Maximum number of conversations allowed for automatic policy discovery on a branch of the scope tree.

20,000,000

Maximum number of total unique workloads (endpoints) allowed for automatic policy discovery run.

15,000,000

Maximum number of exclusion filters in Default Policy Discovery config.

100

Maximum number of exclusion filters allowed per workspace.

100

Maximum number of submissions allowed for Automatic Policy Discovery.

5

Concrete policies

Aggregate size of policies on agents installed on non-Kubernetes workloads.

2.5 MB

(About 2000 policies, depending on complexity)

Aggregate size of policies on agents installed on Kubernetes nodes.

7.5 MB

(About 6000 policies, depending on complexity)